About OWASP CRS
The OWASP Core Rule Set, or CRS, is a set of generic attack detection rules meant to be loaded into a web application firewall. It works with OWASP ModSecurity, OWASP Coraza and other compatible engines rather than running as a standalone application. The rules are written to protect web applications against a broad range of attacks while keeping false alerts to a minimum.
Coverage is aimed at threats such as those in the OWASP Top Ten. The project invites reports of false positives, false negatives and evasions through GitHub issues, and asks for the installed version and relevant audit log portions to help reproduce each case. Discussion takes place in a Google Group and the coreruleset channel on OWASP Slack, and the project website links to installation and configuration resources.
The ruleset is released under the Apache-2.0 license, with copyright held by Trustwave and contributors up to 2020 and by the CRS project afterward. The latest release listed is v4.29.0. Because it is a ruleset, it suits teams already operating a compatible WAF who want maintained, community-reviewed detection logic.
Key features
- Generic attack detection rules for web applications
- Compatible with ModSecurity and Coraza
- Targets the OWASP Top Ten threat categories
- Tuned to limit false positives
- Community channels for reporting evasions
Good fit for
- βAdding baseline protection to a WAF
- βHardening public-facing web applications
- Built with
- Python
- Tags
- waf
- owasp
- security
- ruleset
- modsecurity
- coraza
- web-security
- open-source
Open-source alternatives to OWASP CRS
See all
BunkerWeb
Security
π‘οΈ Open-source and cloud-native Web Application Firewall (WAF)
AGPL-3.0vs Cloudflareβ 11k
ModSecurity
Security
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Ap
Apache-2.0vs Cloudflareβ 9.8k
SafeLine
Security
CyberServal open-source WAF is a self-hosted WAF with 20.9K GitHub stars. Block SQL inject
GPL-3.0vs Cloudflareβ 23k
CrowdSec
Security
Open-source IDS/IPS, WAF and bot detection for Linux, Windows, Docker and Kubernetes, with
MITvs Cloudflareβ 15k
DefectDojo
Security
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
BSD-3-Clausevs Tenableβ 5k
ClamAV
Security
ClamAV - Documentation is here: https://docs.clamav.net
GPL-2.0vs Avastβ 7.3k
SaaS alternatives to OWASP CRS
See all
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS
42Crunch
Security
API security platform that audits OpenAPI definitions and protects APIs at runtime
SaaS
Abnormal Security
Security
Behavior-based cloud email security that blocks phishing and account takeover
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Akeyless
Security
SaaS secrets management and machine identity platform for apps and pipelines
SaaS
Arctic Wolf
Security
Managed detection and response with a 24x7 security operations center
SaaS

